Earlier quoted context omitted.
Connecting entertainment systems to flight control sounds very wrong. Connecting entertainment systems to flight management would be common; it should be one-way communication (entertainment can only read FMS data, not send any), for the purpose of driving the moving map displays for passengers.
The moving map could easily be fed from a separated consumer grade GPS. Same for all other metrics that the median passenger would care about (height, speed over ground), except for the ever-impressive outside temperature.
A Boeing Code Leak Exposes Security Flaws Deep in a 787's Guts
71–80 of 277 posts
Re: A Boeing Code Leak Exposes Security Flaws Deep in a 787's Guts
#72Earlier quoted context omitted.
Because by keeping it closed, it is safer. /s Most executives care about profits, security is simply not important. Even if an engineer explains that he needs more time to properly secure something, he will be asked to cut corners. Then, when shit hits the fan the executive will make a "pikachu face" and engineer will get fired for not properly implementing security.
Having met a fair number of top executives I don’t feel this is true. People at the top do care quite a bit, and put personal pride into their company being good. But all low level decisions are made downstream, and middle managers are far less personally invested. Reactions to bad press are reactions. Hard to say whether it reflects anyone’s reality.
Re: A Boeing Code Leak Exposes Security Flaws Deep in a 787's Guts
#73Earlier quoted context omitted.
> Boeing maintains that other security barriers in the 787's network architecture would make that progression impossible. They probably do something to that effect
The longer I'm alive the more firmly I commit to never assume anything. I have seen things. Terrible things.
Re: A Boeing Code Leak Exposes Security Flaws Deep in a 787's Guts
#74It seems insane that all this code isn't just open source by default. No one's going to be able to rip off airlines by stealing it, you still need to have a company that, you know, sells planes. Keeping it closed seems like a full admission that "there are probably a bunch of bugs in here and we don't want people to see them"
Re: A Boeing Code Leak Exposes Security Flaws Deep in a 787's Guts
#75Earlier quoted context omitted.
Because by keeping it closed, it is safer. /s Most executives care about profits, security is simply not important. Even if an engineer explains that he needs more time to properly secure something, he will be asked to cut corners. Then, when shit hits the fan the executive will make a "pikachu face" and engineer will get fired for not properly implementing security.
Having met a fair number of top executives I don’t feel this is true. People at the top do care quite a bit, and put personal pride into their company being good. But all low level decisions are made downstream, and middle managers are far less personally invested. Reactions to bad press are reactions. Hard to say whether it reflects anyone’s reality.
Re: A Boeing Code Leak Exposes Security Flaws Deep in a 787's Guts
#76Who thought that having any communication path from the passenger entertainment system to flight control was a good idea?
You want communications from the flight controls to the maintenance system. And you want communications from the entertainment system to the maintenance system, so technicians have a single list of everything that needs fixing. It's hard to implement strict one-way communications -- usually you at least need some kind of ACK for reliable transmission. Put all those together with a vulnerability in the middle, and you…
Re: A Boeing Code Leak Exposes Security Flaws Deep in a 787's Guts
#77Who thought that having any communication path from the passenger entertainment system to flight control was a good idea?
Or to driving control! But, engineers keep making this mistake. Hackers were able to take over Jeeps via the entertainment system: https://www.bbc.com/news/technology-33650491 HN discussion: https://news.ycombinator.com/item?id=9942647
Re: A Boeing Code Leak Exposes Security Flaws Deep in a 787's Guts
#78Earlier quoted context omitted.
i dont think i know of any airline company that prides themselves on the code they wrote?
Airbus. Not a matter of pride, but you don't want to help your competitors offer the same capabilities as you for $0 R&D costs
Re: A Boeing Code Leak Exposes Security Flaws Deep in a 787's Guts
#79...an FAA spokesperson wrote in a statement to WIRED that it's "satisfied with the manufacturer’s assessment of the issue." Can't help but read this as: "We don't have a clue and depend on the manufacturer to tell us everything is 5 by 5."
Re: A Boeing Code Leak Exposes Security Flaws Deep in a 787's Guts
#80From the article: "He was surprised to discover a fully unprotected server on Boeing's network, seemingly full of code designed to run on the company's giant 737 and 787 passenger jets, left publicly accessible and open to anyone who found it. So he downloaded everything he could see." Is that even legal? Will he ever be allowed to cross the US border after admitting this?
Generally no. There is a difference between being unprotected and being open to the public. While in some cases a person can claim to not have known and proving mens rea for such a crime is much harder than if it was protected and the protection had to be bypassed, it isn't impossible.
Such laws are selectively enforced, but being this is Boeing, you can expect it will be enforced on their behalf if they have any desire for it to be (given the current PR issues and the impact this might have, they might let this one go, at least for the time being).